
20
660
A member was added to a security-enabled universal group.
661
A member was removed from a security-enabled universal group.
662
A security-enabled universal group was deleted.
663
A security-disabled universal group was created.
664
A security-disabled universal group was changed.
665
A member was added to a security-disabled universal group.
666
A member was removed from a security-disabled universal group.
667
A security-disabled universal group was deleted.
668
A group type was changed.
684
The security descriptor of administrative group members was set.
Note:
Every 60 minutes on a domain controller, a background thread searches all
members of administrative groups (such as domain, enterprise, and schema
administrators) and applies a fixed security descriptor on them. This event is logged.
685
Name of an account was changed.
The event IDs above can be useful when creating custom alerts to monitor any software suite, for
example, MOM. Most operational management software can be customized with scripts in order to
capture or flag events based on the event IDs above.
Audit Directory Service Access
Member Server Default
Legacy Client
Enterprise Client
High Security Client
No auditing
Success Failure
Success Failure
Success Failure
The
Audit directory service access
setting determines whether to audit the event of a user accessing a
Microsoft Active Directory® directory service object that has its own system access control list (SACL)
specified. Setting
Audit directory service access to No Auditing
makes it difficult or impossible to
determine what Active Directory objects may have been compromised during a security incident.
There will be no audit record evidence available for analysis after a security incident if the values for
this setting are not set to
Success
and
Failure.
Configuring
Audit directory service access
to
Success
generates an audit entry each time that a user successfully accesses an Active Directory object with a
specified SACL. Configuring this setting to
Failure
generates an audit entry each time that a user
unsuccessfully attempts to access an Active Directory object with a specified SACL.
Event ID
Event Description
566
A generic object operation took place.